PluginProbe
Pay with Vipps and MobilePay for WooCommerce / 6.2.6
Pay with Vipps and MobilePay for WooCommerce v6.2.6
6.2.6 6.3.0 6.2.5 6.2.4 6.2.3 6.2.2 6.2.1 6.2.0 6.1.10 6.1.9 6.1.8 6.1.7 6.1.6 6.1.5 6.1.4 6.1.3 6.1.2 6.1.1 6.1.0 6.0.5 6.0.4 6.0.3 6.0.2 6.0.1 6.0.0 All 189 releases
← All changes | payment/WC_Gateway_Vipps.class.php +9 -3 6.2.0 → 6.2.6 View file →
@@ -3190,9 +3190,14 @@
3190 3190 $is_base64 = $shipping_table ? ( $shipping_table['_is_base64'] ?? false) : false;
3191 3191
3192 3192 if (is_array($shipping_table) && isset($shipping_table[$key])) {
3193 3193 $decoded = $is_base64 ? @base64_decode($shipping_table[$key]) : $shipping_table[$key];
3194 - $shipping_rate = $decoded ? @unserialize($decoded) : null;
3194 +
3195 + // Ensure no shop manager has injected an evil object (that they would have had to add as a plugin) here. IOK 2026-09-18
3196 + $allowed_classes = apply_filters('woo_vipps_express_checkout_allowed_shipping_classes', [WC_Shipping_Rate::class, \stdClass::class]);
3197 + $shipping_rate = $decoded ? @unserialize($decoded, ['allowed_classes' => $allowed_classes]) : null;
3198 + $shipping_rate = is_a($shipping_rate,'WC_Shipping_Rate') ? $shipping_rate : null;
3199 +
3195 3200 if (!$shipping_rate) {
3196 3201 $this->log(sprintf(__("%1\$s: Could not deserialize the chosen shipping method %2\$s for order %3\$d", 'woo-vipps'), Vipps::ExpressCheckoutName(), $method, $order->get_id()), 'error');
3197 3202 $this->log(sprintf(__("Serialized data was %1\$s", 'woo-vipps'), $decoded), 'error');
3198 3203 } else {
@@ -3758,9 +3763,9 @@
3758 3763 }
3759 3764 do_action('woo_vipps_payment_complete_at_shutdown', $order, $this);
3760 3765 } catch (Exception $e) {
3761 3766 // This is/should be non-critical so just log it.
3762 - $this->log(sprintf(__("Could not do all payment-complete actions on %1\$s order %2\$d: %3\$s ", 'woo-vipps'), Vipps::CompanyName(), $orderid, $e->etMessage()), "error");
3767 + $this->log(sprintf(__("Could not do all payment-complete actions on %1\$s order %2\$d: %3\$s ", 'woo-vipps'), Vipps::CompanyName(), $orderid, $e->getMessage()), "error");
3763 3768 }
3764 3769 }
3765 3770
3766 3771 // This is run on payment complete. Per default will it only add a link to the order confirmation page, but
@@ -3867,9 +3872,9 @@
3867 3872
3868 3873 $contents = WC()->cart->get_cart_contents();
3869 3874 $contents = apply_filters('woo_vipps_create_express_checkout_cart_contents',$contents);
3870 3875 try {
3871 - $cart_hash = md5(json_encode(wc_clean($contents)) . WC()->cart->total);
3876 + $cart_hash = WC()->cart->get_cart_hash();
3872 3877 $order = new WC_Order();
3873 3878 $order->set_status('pending');
3874 3879 $order->set_payment_method($this);
3875 3880 if ($ischeckout) {
@@ -3880,8 +3885,9 @@
3880 3885 }
3881 3886 // We use 'checkout' as the created_via key as per requests, but allow merchants to use their own. IOK 2022-09-15
3882 3887 $created_via = apply_filters('woo_vipps_express_checkout_created_via', 'checkout', $order, $ischeckout);
3883 3888 $order->set_created_via($created_via);
3889 + $order->set_cart_hash($cart_hash);
3884 3890
3885 3891 $dummy = sprintf(__('Vipps Express Checkout', 'woo-vipps')); // this is so gettext will find this string.
3886 3892 $dummy = sprintf(__('Vipps Checkout', 'woo-vipps')); // this is so gettext will find this string.
3887 3893